Privacy, in plain English
We handle people's financial documents, so we hold ourselves to a simple standard: keep as little as possible, be honest about all of it, and never touch what we don't need.
Last updated: June 2026
What we never keep
These never get saved to our systems. Full stop.
| We never store… | Why it's safe |
|---|---|
| Your uploaded statement file | It's processed to create your output, then discarded. We don't archive uploads. |
| Your name (account holder) | Even though it appears on the statement, we don't save the account-holder name. |
| Your bank login | We never ask for it. There is no bank connection — you upload, we read, done. |
| Your full IP address | We keep only a shortened, region-level version (see below), never the precise address. |
| Your card number | Payments are handled by Stripe; we never see or store your full card number. |
What we hold briefly, then delete
To let you actually download your converted file, we have to hold the result for a short time. We do this as privately as possible:
| Held briefly… | How we protect it |
|---|---|
| Your converted data | The extracted transactions, amounts, and dates are kept only so you can download them. While held, the data is encrypted at rest, the account-holder name is removed, and it is automatically deleted after a couple of hours (currently 2 hours). We don't use it for anything else. |
What we do keep (and why)
To run the service, fix problems, and decide which banks to add next, we keep a small amount of operational information. None of it is your financial data.
| We keep… | Why |
|---|---|
| Your email | Only if you create an account, so you can sign in and we can support you. Passwordless — we don't store a password. |
| Which bank & how many transactions | The bank name and a count — so we can improve accuracy and prioritize coverage. Not the transactions themselves. |
| Whether it worked | Success or error (and a short error label) so we can find and fix bugs. |
| Your plan & usage count | To apply your free/paid limits and bill correctly. |
| A region-level IP | A truncated IP (e.g. 75.2.x.x) for basic security and to understand roughly where customers are. Auto-deleted after 30 days. |
How long we keep things
- Your uploaded file: discarded right after it's converted — not retained.
- Your converted data: held encrypted only long enough to download (currently up to 2 hours), then automatically deleted.
- Operational analytics (bank, counts, region-level IP): automatically deleted after 30 days.
- Your account & billing records: kept while your account is active, and removed on request.
Your choices
- Access or delete your data. Email us and we'll provide or delete the information associated with your account.
- Use it without an account. The free converter works without signing in; then we have no email tied to your use at all.
- Opt out. If you're a California resident, you have rights under the CCPA/CPRA, including to know what we collect and to request deletion. We honor these for everyone, not just California.
Security
Data is encrypted in transit and at rest. We keep the amount of information we hold deliberately small — the less we store, the less there is to ever go wrong.
Contact us
Questions, data requests, or deletion requests: legal@ledgerliftapp.com. We are 1001649051 Ontario Inc. o/a Ledgerlift, 57 Chatham Street, Hamilton, ON L8P 2B3, Canada.